Local Denial of Service Vulnerability in grep by GNU
CVE-2015-1345

Currently unrated

Key Information:

Vendor
Gnu
Status
Vendor
CVE Published:
12 February 2015

Summary

The bmexec_trans function in kwset.c of grep versions 2.19 through 2.21 is susceptible to a local denial of service attack. By providing crafted input when using the -F option, local users can trigger an out-of-bounds heap read, leading to a crash of the application. This vulnerability poses a risk of service disruption for systems relying on these versions of grep.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.